Security/privacy analysis of biometric hashing and template protection for fingerprint minutiae
Biyometrik kıyım için güvenlik/mahremiyet analizi ve parmak izi olay noktaları için şablon koruma
- Tez No: 434060
- Danışmanlar: DOÇ. DR. HAKAN ERDOĞAN
- Tez Türü: Doktora
- Konular: Elektrik ve Elektronik Mühendisliği, Electrical and Electronics Engineering
- Anahtar Kelimeler: Makine öğrenmesi yöntemleri, Yüz tanıma, Örüntü tanıma, Machine learning methods, Face recognition, Pattern recognition
- Yıl: 2016
- Dil: İngilizce
- Üniversite: Sabancı Üniversitesi
- Enstitü: Mühendislik ve Fen Bilimleri Enstitüsü
- Ana Bilim Dalı: Elektrik-Elektronik Mühendisliği Ana Bilim Dalı
- Bilim Dalı: Belirtilmemiş.
- Sayfa Sayısı: Belirtilmemiş.
Özet
Bu tez cal sması iki ana par cadan olu smaktad r.İlk kı sı m biyometrik kı yı m (hash) y önteminin g üvenli gini ve mahremiyetini ele almaktad r. İkinci k ısı m ise parmak izi olay noktalar i cin sabit uzunlukta bir vekt or ve k ıyı m olu sturma y öntemi sunmaktad r. Biyometrik sistemlere h zla artan ilgi, g üvenlik ve mahremiyet problemlerini arttırma ve dolay s yla biyometrik sablon koruma y öntemlerinin geli stirilmesini de beraberinde getirmiştir. Biyometrik kı yı m, ki sinin biyometrisi ile ki sisel bir gizli anahtar birle stirerek g uvenli bir ikili (binary) sablon olu sturur ve iki unsurlu bir biyometrik do ğrulama y öntemi sunar. Bu tez cal şması , biyometrik kı yı m y öntemini hem teorik a çıdan hem de pratik uygulama y ön ünden analiz etmektedir. Biyometrik kı yı mı n teorik de gerlendirmesi kapsamı nda binomial da ğı l ımı n serbestlik derecesine dayal entropi kestirimini kullanan sistematik bir y öntem anlatı lmaktad r. Buna ek olarak, y üz imgesi k ıyı mı na y önelik özg ün g üvenlik ve mahremiyet ataklar sunulmaktad r. Bu ataklar ile ki sinin gizli anahtar n n art niyetli bir saldı rganca bilindi ği durumlarda biyometrik taraf ından sa ğlanan ilave koruma miktar ol c ulmektedir. Bu ataklardan ikisi bir-bit s k st rmal alg lama kullanan seyrek i saret geri kazan ımı na dayanmaktadı r. Di ger iki atak ise en k üçük i saret boyu çözümlerine dayanmaktad r. Bunlara ek olarak b üyük bir y üz veritaban na dayalı g okku sa gı ata gı da sunulmaktad ır. Sonu çlar g östermektedir ki, ki sisel anahtar ın sald ırgan tarafı ndan bilindi ği durumda biyometrik sablon a cçığa çı kma tehlikesi ile kar şı kar şıya kalmakta ve aynı zamanda sistem de ciddi tehdit altı nda bulunmaktad r. Parmak izi, y uksek ay rdedicili gi ve ba sarı m ı dolayı sı yla pek cok farklı biyometrik ozellik arası ndan tercih edilmektedir. Parmak izi tan ma sistemlerinin tamamına yakı n sı ralı olmayan olay noktalar nın konum ve y ön bilgilerini kullanmaktadı r. Fuzzy commitment ve di ger modern kriptogra k alternatifler gibi ileri biyometrik sablon koruma y öntemleri sabit uzunlukta bir öznitelik vekt ör une ihtiya ç duymaktad r. Dolayı sı yla, bu y öntemler do ğası gere gi farklı sayı da olan parmak izi olay noktalar ını korumak i cin kullan lamamaktad r. Bu tez cal smas , parmak izi olay noktalar k umesini d onmelere de gi simsiz ve sabit uzunlukta bir vekt or olarak ifade eden, özg ün ve ge cerlili ği deneysel olarak g österilmi s bir y öntem sunmaktad r. Bu sayede biyometrik sablon koruma y öntemlerinin ciddi bir performans kayb ı olmadan parmak izi tanı ma i cin kullan labilmesi sa glanm ıstı r. Sunulan y öntem, her bir olay noktası etrafı ndaki yerel g osterimleri evrensel arka plan modeli (UBM) olarak adlandı r ılan bir Gaussian karı sı m modeli ile modellenen g ozlemler olarak kullanmaktad r. Her bir parmak izi i cin, UBM ile olan do ğrultusuna g ore birinci dereceden istatistiklerin bir s uper-vekt ör ünü olu şturulmakta ve bu s upervektörler, do ğrulama i şleminde kullanı lmak üzere her bir ki şinin do ğrusal karar destek makinesi (SVM) modelini öğrenmek i cin kullan ılmaktad r. Ayr ca, hem sabit uzunluktaki s uper-vekt or hem de do ğrusal SVM modeli ikili bir kı yı ma d ön ü st ür ülm ü ş ve kar şı la ştı rma i şlemi bu ikisi aras ndaki Hamming uzakl ığının hesaplanması na indirgenmi stir. B öylelikle, parmak izi olay noktaları homomor k (benzer yapı lı ) şifreleme temelli kriptografi k alternatifler ile korunabilir hale gelmi stir.
Özet (Çeviri)
This thesis has two main parts. The rst part deals with security and privacy analysis of biometric hashing. The second part introduces a method for xed-length feature vector extraction and hash generation from ngerprint minutiae. The upsurge of interest in biometric systems has led to development of biometric template protection methods in order to overcome security and privacy problems. Biometric hashing produces a secure binary template by combining a personal secret key and the biometric of a person, which leads to a two factor authentication method. This dissertation analyzes biometric hashing both from a theoretical point of view and in regards to its practical application. For theoretical evaluation of biohashes, a systematic approach which uses estimated entropy based on degree of freedom of a binomial distribution is outlined. In addition, novel practical security and privacy attacks against face image hashing are presented to quantify additional protection provided by biometrics in cases where the secret key is compromised (i.e., the attacker is assumed to know the user's secret key). Two of these attacks are based on sparse signal recovery techniques using one-bit compressed sensing in addition to two other minimum-norm solution based attacks. A rainbow attack based on a large database of faces is also introduced. The results show that biometric templates would be in serious danger of being exposed when the secret key is known by an attacker, and the system would be under a serious threat as well. Due to its distinctiveness and performance, ngerprint is preferred among various biometric modalities in many settings. Most ngerprint recognition systems use minutiae information, which is an unordered collection of minutiae locations and orientations. Some advanced template protection algorithms (such as fuzzy commitment and other modern cryptographic alternatives) require a xed-length binary template. However, such a template protection method is not directly applicable to ngerprint minutiae representation which by its nature is of variable size. This dissertation introduces a novel and empirically validated framework that represents a minutiae set with a rotation invariant xed-length vector and hence enables using biometric template protection methods for ngerprint recognition without signi cant loss in veri cation performance. The introduced framework is based on using local representations around each minutia as observations modeled by a Gaussian mixture model called a universal background model (UBM). For each ngerprint, we extract a xed length super-vector of rst order statistics through alignment with the UBM. These super-vectors are then used for learning linear support vector machine (SVM) models per person for veri cation. In addition, the xed-length vector and the linear SVM model are both converted into binary hashes and the matching process is reduced to calculating the Hamming distance between them so that modern cryptographic alternatives based on homomorphic encryption can be applied for minutiae template protection.
Benzer Tezler
- Improved security and privacy preservation for biometric hashing
Biyometrik kıyım için arttırılmış güvenlik ve mahremiyet koruması
ÇAĞATAY KARABAT
Doktora
İngilizce
2013
Elektrik ve Elektronik MühendisliğiSabancı ÜniversitesiElektronik Mühendisliği Ana Bilim Dalı
YRD. DOÇ. DR. HAKAN ERDOĞAN
- Kritik altyapılar için birleşik yüz ve parmak izi tanıma ile erişim kontrolü
Integrated face and fingerprint recognition for secure access control in critical infrastructures
OSMAN TANYELİ
Yüksek Lisans
Türkçe
2026
Savunma ve Savunma TeknolojileriGazi ÜniversitesiBilgi Güvenliği Mühendisliği Ana Bilim Dalı
PROF. DR. HÜSEYİN ÇAKIR
- Türkiye'de iç savunmada yapay zekanın etik açıdan değerlendirilmesi
Ethical evaluation of artificial intelligence in the field of internal security in Turkey
FATİH KAAN BOZER
Yüksek Lisans
Türkçe
2025
Kamu YönetimiSinop ÜniversitesiSiyaset Bilimi ve Kamu Yönetimi Ana Bilim Dalı
DOÇ. DR. ÖZGE ÖNKAN
- Privacy-preserving mechanisms for face verification systems
Yüz doğrulama sistemleri için gizliliği koruyucu mekanizmalar
MARAM H. W. ALAGHBAR
Yüksek Lisans
İngilizce
2024
Elektrik ve Elektronik MühendisliğiYıldız Teknik ÜniversitesiElektronik ve Haberleşme Mühendisliği Ana Bilim Dalı
PROF. DR. TÜLAY YILDIRIM
- Çevrim içi sınavlarda uygulanabilecek kimlik doğrulama şemalarına ilişkin öğretim elemanı ve üniversite öğrencilerinin görüşlerinin incelenmesi
Analyzing of the opinions of instructors and university students in regards to authentication schemes that can be applied in online exams
CANAN BATTAL
Yüksek Lisans
Türkçe
2023
Bilim ve TeknolojiNecmettin Erbakan ÜniversitesiBilgisayar ve Öğretim Teknolojileri Eğitimi Ana Bilim Dalı
DOÇ. DR. ŞEMSEDDİN GÜNDÜZ